
The people running corporate security teams are quietly updating their resumes, and the AI everyone blames for burning them out is not the reason. Over the past year, one in four security chiefs, 26%, thought seriously about walking away from the job, a number Splunk field chief information security officer (CISO) Kirsty Paine drew from two internal surveys. What changed is who carries the risk. According to Splunk’s The CISO Report, 96% of CISOs now own AI governance and 78% fear personal liability for a data breach they must answer for to a regulator or their board.
AI Governance Became the CISO’s Job, Liability Included
Michael Fanning, Splunk’s CISO, calls the role operating in the eye of the storm, and the survey of 650 global security leaders explains why. Nearly every respondent, 96%, now owns AI governance and risk management across the enterprise. The share worried about personal liability climbed to 78%, up from just over half a year earlier, a jump we reported as AI governance mandates spread. Splunk, the Cisco-owned security and observability firm, frames this as an expanded mandate; to the executive holding it, the mandate reads as accountability arriving faster than authority.
Shadow AI Expands the Attack Surface the CISO Must Answer For
Most CISOs actually like the AI on their own consoles, which is what makes the exit numbers strange. In the same report, 92% say AI lets their teams review more security events and 89% report better data correlation. Nine in ten analysts in a security operations center (SOC) poll said AI improved their workload. That upside is genuine, and a separate CISO survey found the same optimism running ahead of the domain controls meant to contain it. The pressure comes from somewhere else. The business keeps opening new AI risk faster than security can govern it. TJ Marlin, CEO of Guardrail Technologies, an AI security provider, puts it plainly. Teams now build applications with vibe coding and wire AI into production without declaring it, creating shadow AI the CISO never approved. With 85% of business leaders lacking basic cybersecurity fluency, the executive who owns AI risk management has the least control over how fast that risk grows.
Three Moves Before the Next AI Agent Ships
The sequence matters: get security into the decision before the AI ships, translate the risk while the board is listening, then build a record that survives review. Each step buys back a piece of the authority the liability already assumes.
Move security upstream of the next shadow AI deployment – Fanning argues security has to be part of the rollout and advocate for safe defaults. With 96% of CISOs already accountable for AI governance, reviewing agents only after they reach production means owning risk you never saw.
Translate the risk into the board’s language before you need the budget – Fanning ties the 85% cybersecurity-fluency gap to a shared vocabulary that puts technical risk in business terms. The CISO who can show a regulator-ready compliance story on incident disclosure spends less time defending personal liability after the fact.
Build for the end-of-tenure audit – Justin Bajko, cofounder and chief strategy officer at Expel, a managed detection and response firm, says to build a program that survives after a CISO’s tenure ends. The scrutiny may come from a regulator, law enforcement, or a potential new employer. That last audience is reading the resumes of the 26% already eyeing the door, the clearest signal for any board still treating AI governance as someone else’s job.
Join our LinkedIn group Information Security Community!











